Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2017-8906

Published: 11 May 2017

An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.4, as used by the x265_encoder_encode dependency in libbpg and other products. A small picture can cause an integer underflow, which leads to a Denial of Service in the process of encoding.

Notes

AuthorNote
msalvatore
Affected code is *NOT* disabled in xenial. Xenial is affected.
Upstream has not released a patch, rather, they have "disabled
'planeClipAndMax' assembly primitives"
ccdm94
it seems like upstream has already closed this issue and will be
providing a fix for it other than the suggested disabling of the
'planeClipAndMax' assembly primitives. Therefore, considering that
this has been deferred for 5+ years and there were no further
changes that allow this to be patched in xenial, xenial will be
marked as ignored.

Priority

Medium

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
x265
Launchpad, Ubuntu, Debian
artful Ignored
(end of life)
bionic Not vulnerable
(affected code is not enabled)
cosmic Not vulnerable
(affected code is not enabled)
disco Not vulnerable
(affected code is not enabled)
eoan Not vulnerable
(affected code is not enabled)
focal Not vulnerable
(affected code is not enabled)
groovy Not vulnerable
(affected code is not enabled)
hirsute Not vulnerable
(affected code is not enabled)
impish Not vulnerable
(affected code is not enabled)
jammy Not vulnerable
(affected code is not enabled)
trusty Does not exist

upstream Needed

xenial Ignored
(see notes)
yakkety Ignored
(end of life)
zesty Ignored
(end of life)

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H